Idolbe Patch

Install the Linux agent

One-line install, supported distributions, systemd service, package updates, uninstall.

The Linux agent is a single static binary that runs as a systemd service under root. It reports the inventory, detects package updates through the distribution's package manager and executes console actions (scripts, updates, reboots, data collections).

Supported systems

FamilyPackage managerTested
Debian, UbuntuaptUbuntu 22.04 and 24.04 (production)
RHEL, Rocky Linux, AlmaLinux, Fedoradnf / yumSupported, community feedback welcome
openSUSE, SLESzypperSupported, community feedback welcome

Architectures: x86_64 and arm64. Requirements: systemd, curl, root access for the install, outbound HTTPS (TCP 443) to the console. Nothing listens on the machine.

macOS: an agent for macOS 12+ (Apple Silicon and Intel, launchd daemon, softwareupdate) ships with the same one-liner but has not been validated on real hardware yet. Treat it as a preview.

Install

Open Getting started in the console and copy the Linux one-liner; it already contains your organization's enrollment key:

curl -fsSL "<console URL>/api/agents/install.sh?key=<your enrollment key>" | sudo bash

The script runs as root, detects the distribution and architecture, downloads the matching binary pre-configured for your organization, verifies its SHA-256 against the value the console sent with it, enrolls the machine and installs the service. It is idempotent: running it again upgrades the agent in place and keeps the endpoint's identity.

Output ends with "Done. This computer is now managed by Idolbe Patch." and the machine appears under Endpoints within a minute.

Unattended provisioning (cloud-init, Ansible, Terraform) can run the same command; unknown enrollment keys are rate-limited per source IP.

What the agent does

  • Check-in every hour: hostname, distribution and kernel, CPU, memory, disks, network, installed packages, uptime, pending reboot (/var/run/reboot-required on Debian and Ubuntu, needs-restarting on RHEL-like systems).
  • Missing updates: apt, dnf/yum or zypper update lists, with security classification where the distribution provides it. In the Deploy Updates wizard, "Only selected" takes package names as title:<package> (for example title:openssl).
  • Commands every 30 seconds: Run Script (bash, as root), Deploy Updates, Deploy Software (.deb, .rpm, .sh), Uninstall Software, Reboot (with a wall message to logged-in users), data source collections written in bash.
  • Self-update: the agent downloads a newer published version at its next check-in, verifies the Ed25519 signature and the SHA-256, then restarts through systemd.

Files, service and logs

PathContent
/usr/local/bin/idolbe-patch-agentThe binary
/etc/idolbe-patch/agent.jsonIdentity and per-endpoint token (mode 0600, root)
/var/log/idolbe-patch/Agent log
/etc/systemd/system/idolbe-patch-agent.serviceThe unit (hardened: private /tmp, no new privileges, restart on failure)

Useful commands:

sudo systemctl status idolbe-patch-agent
sudo journalctl -u idolbe-patch-agent -n 100
sudo idolbe-patch-agent -version
sudo idolbe-patch-agent -run        # one foreground check-in + command poll, for debugging

Uninstall

sudo idolbe-patch-agent -uninstall

The agent notifies the console (the endpoint disappears immediately), removes the service, then deletes its configuration, logs and binary. When an organization is closed from Subscription → Close Account, every online agent receives this order automatically. Deleting the endpoint from the console has the same effect at the agent's next check-in (agents 0.11.4 and later); re-running the one-liner enrolls the machine again.

Moving a machine to another organization

Uninstall, then run the one-liner of the new organization. An enrolled machine only re-enrolls into the organization whose key it holds.